Vulnerabilities > Gitlab > Gitlab > 12.3.1

DATE CVE VULNERABILITY TITLE RISK
2020-01-03 CVE-2019-19311 Cross-site Scripting vulnerability in Gitlab
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
network
gitlab CWE-79
3.5
2020-01-03 CVE-2019-19254 Information Exposure vulnerability in Gitlab
GitLab Community Edition (CE) and Enterprise Edition (EE).
network
low complexity
gitlab CWE-200
5.0
2020-01-03 CVE-2019-19088 Path Traversal vulnerability in Gitlab
Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.
network
low complexity
gitlab CWE-22
7.5
2020-01-03 CVE-2019-19087 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).
network
low complexity
gitlab CWE-732
4.0
2020-01-03 CVE-2019-19086 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).
network
low complexity
gitlab CWE-732
4.0
2019-12-20 CVE-2019-15584 Resource Exhaustion vulnerability in Gitlab
A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.
network
low complexity
gitlab CWE-400
4.0
2019-12-18 CVE-2019-5487 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.
network
low complexity
gitlab
5.0
2019-12-18 CVE-2019-5486 Improper Authentication vulnerability in Gitlab
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
network
low complexity
gitlab CWE-287
6.5
2019-12-18 CVE-2019-15591 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
network
low complexity
gitlab
4.0
2019-12-18 CVE-2019-15589 Unspecified vulnerability in Gitlab
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
network
low complexity
gitlab
6.5